Five takeaways from Raleigh’s Official Cybersecurity Summit 2026

Let me start with the important part: last Wednesday in Raleigh, the heat index hit somewhere around 105 degrees, which means the walk from my car to the front doors of the Hilton North Hills counted as both a cardio workout and a controlled burn. I’ve dealt with plenty of things that make me sweat in this job… a 2am ransomware alert, an auditor asking “so where’s your asset inventory”…but nothing prepared me for standing in the parking lot in a polo shirt while the asphalt actively shimmered. At one point I’m pretty sure my badge lanyard got a sunburn. Anyway. Cybersecurity conference. Let’s talk about that.

I spent one very full day at the CyberRisk Alliance’s Official Cybersecurity Summit in Raleigh, notebook in one hand, complimentary tote bag full of stress balls in the other. One day sounds light compared to the usual multi-day industry mega-conferences, but they packed it wall to wall: a keynote, two panels, a fireside chat, an FBI closing briefing, and a rotating cast of vendor presentations in between. I came home genuinely reenergized about where the security landscape is headed, instead of the usual doom-and-gloom you’d expect from a day of AI-threat talk. 

Here’s what stuck with me.

 

Small weaknesses don’t stay small anymore

The first theme is the one that hit hardest, because it’s a blind spot security practitioners live in every day. On my desk, a low-priority vulnerability sits in a queue and waits its turn. But AI doesn’t look at things in isolation the way our scoring systems do. It’s very good at finding how that “low priority” item connects to an exposed identity, a forgotten API token, or some trusted business process nobody’s given a second thought to in a while. Individually, none of it looks urgent. Strung together by something fast enough to actually do the connecting, it’s a way in.

The takeaway for my day-to-day: stop scoring vulnerabilities like they live on an island. Context-driven prioritization is the whole game now.

 

We need to stop promising perfection

This was almost a relief to hear said out loud: the goal isn’t to promise leadership that nothing will ever get through, because it will. The goal is resilience; containing compromise, protecting the data that actually matters, cutting downtime, and getting better outcomes when something does go wrong.

That reframe changes how I want to talk to people outside of security too. Instead of every conversation being “we stopped X attacks this month,” it’s “here’s how fast we’d notice, here’s how fast we’d contain it, here’s what stays running.” Attackers can now move from discovery to exploitation a lot faster than they used to, which makes real-time visibility and fast containment less of a nice-to-have and more of the whole job.

 

AI doesn’t replace judgment, it just moves faster than we do

AI can do a lot of the heavy lifting — chewing through logs, flagging anomalies, drafting a response plan — but people still have to be responsible for the decisions that matter. Trust comes from clear approval points, reasoning you can see, and a name attached to the outcome. The best use of automation isn’t replacing people, it’s removing the repetitive stuff so judgment and accountability have room to actually happen.

Garbage in, garbage at scale

Less dramatic than some of the other themes, but it stuck with me: AI amplifies whatever it’s fed. Clean, structured, governed data leads to better decisions. Messy or inconsistent data doesn’t just produce a slightly worse answer, it scales confusion, bias, and operational risk right along with everything else. If our asset inventory and identity data are a mess today, bolting AI on top doesn’t fix that. It just makes the mess move faster.

Finally, a legitimate excuse to go bug the data team about cleaning things up.

 

Security has to show up earlier

Last one: security can’t be the final go/no-go review anymore. As more people across the business use AI to build code, workflows, and applications, SecOps needs to help shape design, access, data use, testing, and deployment from day one — not show up at the end with a clipboard and a “no.”

Underneath all five of these is the same idea, really: identity, endpoints, and data are the actual front lines now, not just the network perimeter. And none of this works without the visibility and understanding what an AI system is doing, why it’s doing it, and who signed off on it. That’s what builds trust, both internally and with whoever we answer to.

 

The main takeaway

None of this is about doing more with more tools. It’s about knowing what to automate, what to keep a human eyeball on, and proving our defenses hold up instead of just assuming they do. Security outcomes over security activity — reduced exposure, faster response, verified recovery — not just a bigger stack of logos on a slide. And the governance behind it all can’t be a document we write once and forget; it has to evolve as fast as the tools do.

That’s a more grounded story than “AI will save us” or “AI will doom us,” and it’s one I’m glad to bring back to my team (and you).

 

Ryan Licht, One Source SOC Analyst

Related articles